Vulnerability CVE-2026-2758: Information

Description

Use-after-free in the JavaScript: GC component. This vulnerability affects Firefox < 148, Firefox ESR < 115.33, Firefox ESR < 140.8, Thunderbird < 148, and Thunderbird < 140.8.

Severity: CRITICAL (9.8)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Published: Feb. 24, 2026
Modified: Feb. 26, 2026
Error type identifier: CWE-416

Fixed packages

Package name
Branch
Fixed in version
Version from repository
Errata ID
Task #
State
firefoxsisyphus148.0-alt1148.0-alt2ALT-PU-2026-3542-2409187Fixed
firefoxsisyphus_loongarch64148.0-alt0.port148.0-alt0.portALT-PU-2026-3960-1-Fixed
firefoxp11148.0-alt2147.0.2-alt1ALT-PU-2026-4175-1409232Testing
firefox-esrsisyphus140.8.0-alt1140.8.0-alt1ALT-PU-2026-3923-2409748Fixed
thunderbirdsisyphus148.0-alt1148.0-alt2ALT-PU-2026-3544-2409185Fixed
thunderbirdsisyphus_riscv64148.0-alt1148.0-alt2ALT-PU-2026-3685-1-Fixed
thunderbirdsisyphus_loongarch64148.0-alt0.port148.0-alt0.portALT-PU-2026-4198-1-Fixed

References to Advisories, Solutions, and Tools

    1. cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:*
      End excluding
      115.33.0

      cpe:2.3:a:mozilla:firefox:*:*:*:*:-:*:*:*
      End excluding
      148.0

      cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:*
      Start including
      128.0
      End excluding
      140.8.0

      cpe:2.3:a:mozilla:thunderbird:*:*:*:*:esr:*:*:*
      End excluding
      140.8.0

      cpe:2.3:a:mozilla:thunderbird:*:*:*:*:-:*:*:*
      End excluding
      148.0